Fixed-Fee Engagement

Find out what the assessor will find, two weeks before they do

A fixed-scope technical audit of your cloud environment, delivery pipeline, or data platform against the framework you are being held to. You get a written control mapping, a prioritized list of findings with the architectural fix for each, and an effort estimate per item. You own the report outright. It is your document, written so your engineers can act on it the day it lands.

Fixed fee · no hourly billing
fixed fee
2 weeks · single platform, up to 20 services
Written report · roadmap · effort estimates
Book a scoping call

Why teams start here

Two weeks of senior engineering against your live environment produces something no proposal can: a precise scope. We map every relevant control to what your system actually does, rank the gaps in the order an assessor will reach them, and attach an effort estimate to each one. It is small enough to approve without a committee and short enough to finish before your next milestone.

That precision is the point. Most teams cannot scope their own remediation. They know something is wrong, they do not know how much, and every proposal they receive is priced against a guess. We replace the guess with a document your engineers, your CFO, and your assessor can all read and agree on.

The report is written to be executed, not to be sold against. Roughly half of audit clients take it and do the remediation with their own engineers, which is exactly what a good roadmap should make possible. The other half bring us back because the scope is already agreed and the work can start immediately.

What you receive

Control mapping

Every relevant control mapped to what your system actually does, with the specific CFR section, 800-53 family, or trust services criterion it answers to.

Prioritized findings

What fails, ranked by the order an assessor will hit it, with the architectural fix for each. Written for engineers, not for a binder.

Effort estimates

Engineer-days per finding so you can budget the remediation, sequence it against your roadmap, or price it out to a vendor.

Evidence gap list

What your system currently cannot prove. Usually the most uncomfortable section, and the one that saves the most time later.

How the two weeks run

Week 1 · Evidence

We look at the system, not the documentation

  • Read-only access to cloud accounts, pipeline, and IaC
  • Architecture and data flow walkthrough with your engineers
  • Evidence pull: logs, retention, identity, access history
  • Two working sessions, roughly 90 minutes each
Week 2 · Findings

We write it up and walk you through it

  • Control mapping and findings drafted
  • Effort estimates attached to each item
  • Live readout with your team, questions answered
  • Final written report delivered

Frameworks we audit against

You name the framework and the target. We map to it.

HIPAA Security Rule FedRAMP Moderate FedRAMP High SOC 2 Type II HITRUST CSF CMMC 2.0 NIST SP 800-53 NIST SP 800-171

What happens after

You leave with a plan you can execute three ways. Your own engineers work the roadmap using the effort estimates as the schedule. You put a real scope in front of vendors and get bids against facts instead of assumptions. Or you engage us for the build, in which case the audit findings become the statement of work and we start on day one from a scope both sides already agree on.

Build engagements run 8 to 12 weeks at fixed fee, and teams with ongoing obligations often move onto a continuous compliance retainer after handoff. See the full practice list for what that covers.

Questions

What do I actually receive?
A written report with a control mapping of your environment against the framework you name, a prioritized findings list, the architectural fix for each, and an effort estimate per finding. It is written for engineers to act on, not for a compliance binder.
Do I have to hire you for the remediation?
No. You own the report and it is written so your own engineers can execute it. Roughly half of audit clients do exactly that, which is the mark of a roadmap that works. The rest bring us back because the scope is already settled and the build can start immediately.
What does it cover, and what does it not?
It covers the technical layer: cloud architecture, CI/CD pipeline, data platform, identity, logging, and evidence. It does not cover workforce training, policy authoring, vendor management, or the administrative safeguards a GRC consultant handles. We audit the systems, not the paperwork.
Is this a certification or a formal assessment?
This is a technical readiness audit: it tells you what an assessor will find before they find it. We are an engineering firm rather than an accredited assessment organization, and deliberately not a 3PAO, because assessors cannot remediate findings they identify without creating an independence conflict. That separation is why teams bring us in alongside their assessor rather than instead of one, and why our output is an engineering roadmap your team can execute rather than a scored report.
What if my environment is bigger than 20 services?
The fee covers a single platform up to roughly 20 services, which fits most teams. Larger or multi-platform estimates are scoped on the call and quoted before anything starts. You will never receive an invoice you did not agree to in advance.
How quickly can you start?
Usually two to three weeks from signature, sooner if you have a fixed assessment date. Tell us the deadline on the first call and we will say plainly whether we can meet it.

Book a scoping call

Thirty minutes. Bring your architecture and your deadline. We will confirm the audit is the right starting point, scope it against your actual environment, and send a written proposal within 48 hours. If you do not need an audit, we will tell you on the call.

Book a 30-minute scoping call
Want a number first? Run the estimator to see your control count and first-cycle cost. No email required.